30 April 2025 / Applied AI / 8 chapters

Restrict reads at the source

From Deciding what a tool-using agent can read and change

Read-only access can still disclose sensitive information, and unrestricted retrieval can bring irrelevant instructions into the model context. Limit what can be queried, which fields are returned and how much material enters one task.

Prefer task-scoped lookup over general search. If a case contains an approved account identifier, the tool can retrieve that account after checking the invoking user's relationship to it. Allowing free-text search across all accounts creates a much larger discovery surface and makes a mistaken query more consequential.

Apply row and tenant boundaries in the source system or trusted gateway. Do not rely on the model to remember a tenant ID. The gateway should derive scope from the authenticated user and task, then reject a conflicting identifier supplied in tool arguments.

Field selection matters as much as row selection. A response-writing task may need contact preference and case history but no bank details, identity documents or internal risk notes. Build a purpose-specific response object instead of passing through the source API's full record.

Attachments need separate treatment. Their names may reveal information, their contents can be large, and uploaded documents can contain instructions that try to influence the agent. Check file type, size, malware controls, classification and task relevance before extraction. Preserve the attachment as untrusted source material. Its text should not be treated as system instruction.

Set result limits and pagination rules. If a lookup returns hundreds of matches, the agent should stop and ask for a narrower identifier rather than choose one from a truncated list. Make truncation explicit in the tool response. When the interface presents a partial result as complete, the model has no evidence that records are missing.

Log which source objects were read, but avoid copying their full contents into the audit log. Object identifiers, field groups, query classification and access decision usually provide enough evidence for review without making another store of private data.

All articles